{"id":63829,"date":"2026-07-18T06:29:57","date_gmt":"2026-07-18T10:29:57","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=63829"},"modified":"2026-07-18T06:29:57","modified_gmt":"2026-07-18T10:29:57","slug":"wordpress-wp2shell-emergency-patch","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/wordpress-wp2shell-emergency-patch\/","title":{"rendered":"WordPress Releases Emergency Patch for Critical wp2shell RCE Flaw"},"content":{"rendered":"<p>The WordPress project has issued an emergency security update to patch a critical chain of vulnerabilities, identified as wp2shell, that allows unauthenticated attackers to execute arbitrary code on vulnerable websites. This flaw, which carries a CVSS score of 9.8, affects WordPress versions 6.9 through 7.0.1 and has already prompted warnings of circulating proof-of-concept (PoC) exploits and early indications of real-world exploitation. As WordPress powers an estimated 500 million websites globally, this vulnerability is particularly significant because it can be exploited against a default installation with no plugins or special preconditions, making it a direct threat to the core platform itself.<\/p>\n<h2>Understanding the wp2shell Vulnerability Chain<\/h2>\n<p>The wp2shell chain was discovered by Adam Kues of <a href=\"https:\/\/searchlightcyber.com\/advisories\/wp2shell\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Searchlight Cyber<\/a> and responsibly disclosed to the WordPress Security Team. The issue consists of two distinct vulnerabilities addressed in the July 17 security release. The first, tracked as CVE-2026-60137, is a high-severity unauthenticated <a href=\"https:\/\/overcentral.com\/en\/claude-sql-injection-festival-tickets\/\" title=\"Claude Exploits SQL Flaw to Issue Free Music Festival Tickets\" data-iacss-internal=\"1\">SQL injection<\/a> flaw. This vulnerability, by itself, is a serious concern for database integrity. However, its true danger is realized when it is chained with a second flaw, CVE-2026-63030, a critical REST API batch-route confusion vulnerability that converts the SQL injection into a full <a href=\"https:\/\/overcentral.com\/en\/airdrop-quick-share-flaws\/\" title=\"Six AirDrop and Quick Share flaws expose 5 billion devices\" data-iacss-internal=\"1\">remote code execution<\/a> (RCE) attack.<\/p>\n<h2>How the REST API Exploit Allows Remote Code Execution<\/h2>\n<p>Security researchers from <a href=\"https:\/\/www.wordfence.com\/blog\/2026\/07\/wordpress-wp2shell-rce\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Wordfence<\/a> have detailed that the RCE originates from the <code>\/wp-json\/batch\/v1<\/code>codecodecodecodecodecode REST API endpoint. The core issue is a desynchronization between route validation and dispatch. This flaw allows attacker-controlled requests to bypass intended security restrictions. By exploiting this route confusion, an attacker can leverage the initial SQL injection to execute malicious code on the server, effectively taking control of the website.<\/p>\n<h2>Patched Versions and Immediate Mitigations<\/h2>\n<p>The patched releases are <a href=\"https:\/\/wordpress.org\/news\/2026\/07\/wordpress-7-0-2-security-release\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">WordPress 7.0.2<\/a>, 6.9.5, and 6.8.6. It is important to note that the 6.8 branch is only affected by the SQL injection vulnerability and not the full RCE chain. Due to the severity of the issues, the WordPress project has enabled automatic security updates for supported vulnerable installations. For organizations unable to apply the patch immediately, a temporary mitigation plugin is available from Searchlight Cyber. This plugin requires authentication before processing batch API requests. As a supplementary measure, administrators can also block anonymous access to the REST API batch endpoint by restricting requests to <code>\/wp-json\/batch\/v1<\/code>codecodecodecodecodecode and the <code>rest_route=\/batch\/v1<\/code>codecodecodecodecodecode parameter at the web application firewall level. It is critical to understand that these workarounds may impact legitimate functionality and should only be used as a stopgap until the official update is applied.<\/p>\n<h2>What Makes This WordPress Core Vulnerability Unusual<\/h2>\n<p>Benjamin Harris, CEO of watchTowr, noted that unauthenticated SQL injection and remote code execution vulnerabilities in the core of a mature CMS like WordPress are relatively uncommon. This rarity makes the disclosure particularly concerning. The security community is already observing PoC exploits in circulation and the first signs of in-the-wild exploitation, indicating how rapidly attackers are moving to weaponize this vulnerability chain against a vast pool of potential targets.<\/p>\n<h2>What Affected Users Should Do Now<\/h2>\n<p>The urgency of this situation cannot be overstated. Every WordPress site administrator must immediately update to the latest patched version: WordPress 7.0.2, 6.9.5, or 6.8.6. Verify that automatic updates have completed successfully on your dashboard. If patching was delayed, it is imperative to review your server for signs of compromise, such as newly deployed backdoors or unexpected files. As a general security practice, always deploy a multi-layered endpoint protection solution with real-time threat detection and behavioral analysis on your server. Furthermore, ensure all administrative accounts use strong, unique passwords and that two-factor authentication is enabled. Switching to a reputable, no-log VPN service when managing your site from public networks is also a recommended step to protect your administrative credentials from interception. These actions are not optional; they are a direct response to a critical, <a href=\"https:\/\/overcentral.com\/en\/cisa-sharepoint-patching\/\" title=\"CISA Orders Patching of Actively Exploited SharePoint Flaws\" data-iacss-internal=\"1\">actively exploited<\/a> threat against the world&#8217;s most popular content management system.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The WordPress project has issued an emergency security update to patch a critical chain of vulnerabilities, identified as wp2shell, that allows unauthenticated attackers to execute arbitrary code on vulnerable websites. This flaw, which carries a CVSS score of 9.8, affects WordPress versions 6.9 through 7.0.1 and has already prompted warnings of circulating proof-of-concept (PoC) exploits [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74668,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/CjjJBZ7.jpg","fifu_image_alt":"WordPress Releases Emergency Patch for Critical wp2shell RCE Flaw","footnotes":""},"categories":[349],"tags":[],"class_list":["post-63829","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/CjjJBZ7.jpg","fifu_image_alt":"WordPress Releases Emergency Patch for Critical wp2shell RCE Flaw","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63829","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=63829"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/63829\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74668"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=63829"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=63829"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=63829"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}